×

Specification-based anomaly detection

  • US 20040098617A1
  • Filed: 11/18/2002
  • Published: 05/20/2004
  • Est. Priority Date: 11/18/2002
  • Status: Active Grant
First Claim
Patent Images

1. A method for network intrusion detection on a network comprising a state machines for processing a plurality of network packets comprising the steps of:

  • determining a state-machine specification for at least one network protocol of interest;

    determining at least one statistical property of interest, wherein each statistical property of interest is associated with a property of the state-machine;

    determining, in a training mode, statistics corresponding to the at least one statistical property of interest;

    initializing a detection mode with the statistics corresponding to the at least one statistical property of interest;

    determining observed statistics corresponding to the at least one statistical property of interest in the detection mode according to network packets processed by the state-machines; and

    comparing the at least one statistical property of interest to the observed statistics corresponding to the at least one statistical property of interest determined in detection mode, and upon determining a significant deviation generating an alarm.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×